# Roles required to create logs

**URL:** <https://discuss.elastic.co/t/roles-required-to-create-logs/211917>\
**Category:** Elasticsearch\
**Created:** [December 15, 2019, 5:34pm UTC](https://discuss.elastic.co/t/roles-required-to-create-logs/211917 "2019-12-15T17:34:34Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matthew\_Petrie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matthew_petrie/32/59145_2.png) [@Matthew\_Petrie](https://discuss.elastic.co/u/Matthew_Petrie)\
**Post date:** [December 15, 2019, 5:34pm UTC](https://discuss.elastic.co/t/roles-required-to-create-logs/211917/1 "2019-12-15T17:34:34Z")

</div>

I'm using the Node.js logger `winston` and `winston-elasticsearch` to send logs to Elastic Cloud (uses [https://www.npmjs.com/package/@elastic/elasticsearch](https://www.npmjs.com/package/@elastic/elasticsearch) under the hood) and am using basic authentication (username & password).

I would like to create a new roll that only allows access to the functions required to add logs into Elasticsearch Cloud? Is there a built in role that is designed for this? I've tried adding the `create` &/or `write` permissions for the indexes but this doesn't work (when I add the `superuser` _role_ it all works as expected)

---

<div class="post-metadata">

**Author:** ![VietCong](https://avatars.discourse-cdn.com/v4/letter/v/e47774/32.png) [@VietCong](https://discuss.elastic.co/u/VietCong)\
**Post date:** [December 15, 2019, 10:05pm UTC](https://discuss.elastic.co/t/roles-required-to-create-logs/211917/2 "2019-12-15T22:05:37Z")

</div>

You can create a new role and assign permission to write to certain indices.

I would give this page a read

[https://www.elastic.co/guide/en/elasticsearch/reference/7.5/security-privileges.html](https://www.elastic.co/guide/en/elasticsearch/reference/7.5/security-privileges.html)

---

<div class="post-metadata">

**Author:** ![Matthew\_Petrie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matthew_petrie/32/59145_2.png) [@Matthew\_Petrie](https://discuss.elastic.co/u/Matthew_Petrie)\
**Post date:** [December 15, 2019, 10:23pm UTC](https://discuss.elastic.co/t/roles-required-to-create-logs/211917/3 "2019-12-15T22:23:27Z")

</div>

@VietCong I have looked at that page and have tried the `create` &/or `write` &/or `create_doc` permissions however these don't let the logs be created (as soon as I switch it to the `superuser` role it all works) - I would have thought one of these roles should have been sufficient?

---

<div class="post-metadata">

**Author:** ![VietCong](https://avatars.discourse-cdn.com/v4/letter/v/e47774/32.png) [@VietCong](https://discuss.elastic.co/u/VietCong)\
**Post date:** [December 15, 2019, 10:28pm UTC](https://discuss.elastic.co/t/roles-required-to-create-logs/211917/4 "2019-12-15T22:28:13Z")

</div>

Matthew,

You need to create a role with those permissions first, then assign the role to your user with role mapping. Then you should be able to do write to the index

I would take a look at this page for role creation example

[https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-put-role.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-put-role.html)

---

<div class="post-metadata">

**Author:** ![Matthew\_Petrie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matthew_petrie/32/59145_2.png) [@Matthew\_Petrie](https://discuss.elastic.co/u/Matthew_Petrie)\
**Post date:** [December 21, 2019, 1:48pm UTC](https://discuss.elastic.co/t/roles-required-to-create-logs/211917/5 "2019-12-21T13:48:18Z")

</div>

@VietCong Yes I've created a role using the above permissions and assigned it to the correct user such as the below however we receive no logs for a role with these permissions. As soon as the user is granted the `superuser` role the logs are ingested again.

 ![Screenshot 2019-12-21 at 13.45.46](https://us1.discourse-cdn.com/elastic/original/3X/d/7/d70df8e076eb22063bfeebcd42d171b01576a5dc.png)

---

<div class="post-metadata">

**Author:** ![VietCong](https://avatars.discourse-cdn.com/v4/letter/v/e47774/32.png) [@VietCong](https://discuss.elastic.co/u/VietCong)\
**Post date:** [December 21, 2019, 4:38pm UTC](https://discuss.elastic.co/t/roles-required-to-create-logs/211917/6 "2019-12-21T16:38:47Z")

</div>

Are you writing from logstash? If so what error do you see from logstash? Also if you could share your role and role mapping results for this user, that would be great

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 18, 2020, 4:38pm UTC](https://discuss.elastic.co/t/roles-required-to-create-logs/211917/7 "2020-01-18T16:38:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
